Skip to content
Noroxi

Pyrocms records

6 published records for vendor pyrocms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 20
  2. 22
  3. 23
  4. 25

Bar: total · dark part: CISA KEV.

All records

6 records
  • PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw.

    CriticalCVSS 9.8Proof of conceptEPSS 53%

    pyrocms · pyrocmsAug 4, 2023

  • PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and ja

    CriticalCVSS 9.0No exploitEPSS 1%

    pyrocms · pyrocmsNov 25, 2022

  • PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin

    HighCVSS 7.1No exploitEPSS 1%

    pyrocms · pyrocmsOct 8, 2020

  • PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.

    MediumCVSS 6.1No exploitEPSS 1%

    pyrocms · pyrocmsAug 1, 2022

  • PyroCMS v3.0.1 Stored Cross-Site Scripting via Admin Redirects

    MediumCVSS 5.3No exploitEPSS 0%

    pyrocms · pyrocmsDec 11, 2025

  • PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted.

    MediumCVSS 4.3No exploitEPSS 1%

    pyrocms · pyrocmsOct 8, 2020